NVMeter reads from /dev/disk* and shells out to smartctl. Although it does
not write to disks, please report security issues responsibly.
Email security@nvmeter.app (placeholder) with subject [NVMeter security].
Include:
- Affected version (
swift run NVMeterApp --versionor build SHA) - macOS version
- Steps to reproduce
- Impact assessment
Please do not open a public GitHub issue for security-relevant problems until we have shipped a fix.
We aim to confirm within 72 hours, ship a patch within 14 days, and credit you publicly unless you ask otherwise.
- Issues caused by a tampered or non-upstream
smartctlbinary. - Permission prompts (the app requires user authorization to read raw disks).
- Crashes from clearly-malformed external
drivedbYAML files.